At a Glance
- Tasks: Lead compliance and data protection efforts while ensuring security frameworks are met.
- Company: Join a rapidly growing tech company with a remote-first culture.
- Benefits: Enjoy 28 days holiday, health insurance, and a flexible work environment.
- Why this job: Make a real impact on data protection and compliance in a dynamic setting.
- Qualifications: Experience in GDPR, ISO27001, and strong communication skills required.
- Other info: Be part of a diverse team that values flexibility and trust.
The predicted salary is between 36000 - 60000 £ per year.
We are seeking an experienced and proactive Compliance Manager & Data Protection Officer (DPO) to lead and maintain our compliance, security and data protection frameworks. This role is critical in ensuring that our systems, data and processes meet regulatory, contractual and certification obligations while supporting commercial growth through strong governance, audit readiness and tender support.
You will act as the company's subject matter expert for information security compliance, UK and EU data protection, working closely with technical teams, leadership and external stakeholders to manage risk and promote a strong security culture across the organisation. Cezanne HR Limited is in a rapidly growing phase, so expect a dynamic and fluid environment with all of the opportunities and challenges this entails. This role will suit a proactive person who thrives on using their initiative, can come up with practical solutions when solving problems and is comfortable with ambiguity. The right candidate will be outcome-focused and adept at managing their own time and priorities to work with impact.
We are a remote-first company, and this role can be a remote role based within the UK or Ireland, or hybrid based in our London or Glasgow offices.
Key Responsibilities- Compliance & Information Security
- Own and maintain the ISO27001 Information Security Management Systems (ISMS).
- Lead and manage external audits and surveillance audits, including ISO27001 certification.
- Plan and run internal audits and risk assessments.
- Maintain policies, procedures and risk registers.
- Ensure alignment with contractual, regulatory and customer security requirements.
- Support adherence to additional security or compliance frameworks adopted by the organisation.
- Data Protection & DPO Duties
- Act as the organisation's Data Protection Officer (DPO) in line with UK GDPR and EU GDPR requirements.
- Monitor and advise on compliance with UK and EU data protection legislation.
- Maintain and improve data protection policies, DPIAs, RoPA, and privacy governance.
- Provide guidance on lawful processing, international transfers, and vendor risk.
- Act as point of contact for regulators (e.g. ICO) and data subjects where required.
- Respond to and manage Data Subject Access Requests (DSARs), Data Protection Impact Assessments (DPIAs) conducted by our customers and any other queries regarding potential data breaches, unauthorised disclosures, or risk based incidents.
- Support incident response and breach management.
- Commercial Support
- Support assurance activities such as due diligence responses, third party assessments, and customer security questionnaires.
- Support sales and account teams with customer assurance and compliance evidence.
- Maintain standard compliance documentation and security packs.
- Participate in customer and supplier audits and due diligence processes.
- Continuous Improvement, Automation & AI Supported Compliance
- Lead projects that modernise compliance processes including content management, workflow automation, data governance tooling, AI assisted risk assessments, and systemisation projects-aligned with the organisation's direction toward process automation.
- Identify opportunities for self service models for customers, partners, and internal teams.
- Drive continuous improvement initiatives to enhance efficiency, transparency, and scalability.
- Stakeholder & Training
- Work cross-functionally to ensure alignment between privacy, security, HR, IT, product, operations, and commercial teams.
- Deliver compliance and data protection training across the business.
- Ensure staff training, awareness, and fair processing commitments are met.
- Promote a strong security and privacy culture.
- Legal / Contractual Support
- Review, interpret, and advise on NDAs, Data Processing Agreements (DPAs), and commercial contract clauses relating to security, privacy, and compliance.
- Collaborate with commercial teams on RFP responses, contract negotiations, and customer risk assessments.
- Ensure alignment between legal commitments and operational reality.
- Essential
- Third level qualification in Law, Business, Cybersecurity, Compliance, Data Protection, IT, or related discipline; OR equivalent professional experience.
- Strong working knowledge of UK GDPR and EU GDPR such as implementing and maintaining GDPR compliance and responding to DSARs, DPIAs, and regulatory queries.
- Experience managing ISO 27001, Cyber Essentials, or similar compliance frameworks.
- Strong understanding of information security controls, risk management, and governance.
- Ability to interpret regulations and apply them pragmatically in a commercial SaaS environment.
- Practical experience managing ISO27001 and leading certification audits and working with certification bodies.
- Excellent written and verbal communication skills, capable of engaging confidently with internal stakeholders, customers, partners, suppliers, auditors, and regulators.
- Experience responding to tenders, RFIs and customer security questionnaires.
- Experience working in a technology led, SaaS based, or data driven environment.
- Desirable
- Experience with additional frameworks (e.g. DORA, Cyber Essentials, EU AI Act).
- Legal, data protection or information security qualifications (e.g. CIPP/E, CIPM, ISO27001 Lead Implementer).
- Exposure to GRC tooling, automation systems, or AI governance frameworks.
- Confident advisor to senior stakeholders.
- Detail-oriented but commercially pragmatic.
- Comfortable working independently and setting priorities.
- Calm and methodical under pressure (especially during audits or incidents).
- 28 days holiday + bank holidays.
- A day off for your birthday.
- £250 working from home budget.
- Health Insurance, Life Assurance, and Income Protection.
- Employee assistance program.
- A culture built on flexibility and trust.
- Regular social events, remotely and in person.
Cezanne HR is an equal opportunity employer, and we value diversity at our company. We do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Compliance Manager & Data Protection Officer (DPO) in London employer: Cezanne
Contact Detail:
Cezanne Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Compliance Manager & Data Protection Officer (DPO) in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the compliance and data protection field. Attend industry events or webinars, and don’t be shy about introducing yourself. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of UK and EU GDPR regulations. Be ready to discuss how you’ve implemented compliance frameworks in past roles. Show us that you’re not just familiar with the rules, but that you can apply them practically!
✨Tip Number 3
Don’t forget to showcase your problem-solving skills! In interviews, share specific examples of how you’ve tackled compliance challenges or improved processes. We love candidates who can think on their feet and come up with practical solutions.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows us you’re genuinely interested in joining our team at Cezanne HR. Let’s make it happen!
We think you need these skills to ace Compliance Manager & Data Protection Officer (DPO) in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with compliance and data protection. We want to see how your skills align with the role of Compliance Manager & DPO, so don’t hold back on showcasing your relevant achievements!
Showcase Your Knowledge: Demonstrate your understanding of UK and EU GDPR regulations in your application. We’re looking for someone who can confidently navigate these frameworks, so include specific examples of how you’ve applied this knowledge in past roles.
Be Clear and Concise: When writing your application, keep it straightforward and to the point. We appreciate clarity, so avoid jargon and ensure your key points stand out. This will help us quickly see why you’re a great fit for the team!
Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at Cezanne
✨Know Your Compliance Frameworks
Make sure you brush up on ISO27001 and GDPR regulations before the interview. Be ready to discuss how you've implemented these frameworks in past roles, as well as any challenges you've faced and how you overcame them.
✨Showcase Your Problem-Solving Skills
Prepare examples of how you've tackled compliance issues or data protection challenges in previous positions. Highlight your proactive approach and ability to come up with practical solutions, especially in dynamic environments.
✨Engage with Stakeholders
Since this role involves working closely with various teams, think about how you've successfully collaborated with different stakeholders in the past. Be ready to share specific instances where your communication skills made a difference.
✨Demonstrate Continuous Improvement Mindset
Cezanne HR is looking for someone who can drive efficiency and scalability. Prepare to discuss any projects you've led that modernised compliance processes or introduced automation, and how these initiatives benefited your previous organisation.